Medium - CVE-2024-11203 - The EmbedPress – Embed PDF, 3D Flipbook, Social...
The EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor plugin for WordPress is vulnerable to Stored...
Medium - CVE-2024-11333 - The HLS Player plugin for WordPress is...
The HLS Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hls_player' shortcode in all versions up to, and including, 1.0.10 due to...
Medium - CVE-2024-11366 - The SEO Landing Page Generator plugin for...
The SEO Landing Page Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to,...
Medium - CVE-2024-11431 - The Ragic Shortcode plugin for WordPress is...
The Ragic Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ragic' shortcode in all versions up to, and including, 1.2 due to insufficient...
Medium - CVE-2024-11458 - The FAQ Builder AYS plugin for WordPress is...
The FAQ Builder AYS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ays_faq_tab' parameter in all versions up to, and including, 1.7.1 due to insufficient...
Medium - CVE-2024-11684 - The Kudos Donations – Easy donations and...
The Kudos Donations – Easy donations and payments with Mollie plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and...
Medium - CVE-2024-11685 - The `Kudos Donations – Easy donations and...
The `Kudos Donations – Easy donations and payments with Mollie` plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of `add_query_arg` without appropriate escaping...
Medium - CVE-2024-11761 - The LegalWeb Cloud plugin for WordPress is...
The LegalWeb Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'legalweb-popup' shortcode in all versions up to, and including, 1.1.2 due to...
Medium - CVE-2024-11786 - The Login with Vipps and MobilePay plugin for...
The Login with Vipps and MobilePay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'continue-with-vipps' shortcode in all versions up to, and...
Medium - CVE-2024-11788 - The StreamWeasels YouTube Integration plugin...
The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-youtube-embed' shortcode in all versions up to, and...